Technique ID,Detection Available,Link,score T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1027,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,55 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1566.001,No,-,54 T1193,No,-,54 T1598.002,No,-,54 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/uncommon_processes_on_endpoint.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/batch_file_write_to_system32.yml,50 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/single_letter_process_on_endpoint.yml,50 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,41 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,41 T1086,No,-,47 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_command_line_argument.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_connhost_exe_force_flag.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,39 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,39 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1105,No,-,42 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,33 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/tor_traffic.yml,33 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1107,No,-,32 T1070.004,No,-,32 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/scheduled_task_deleted_or_created_via_cmd.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,26 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,26 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,22 T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,22 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,25 T1082,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_information_discovery_detection.yml,25 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_remote_thread_into_lsass.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_lsass_dump_with_taskmgr.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump.yml,17 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/dump_lsass_via_procdump_rename.yml,17 T1059.005,No,-,27 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1192,No,-,26 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_creating_lnk_file_in_suspicious_location.yml,25 T1598.003,No,-,26 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1005,No,-,24 T1083,No,-,24 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1016,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_processes_used_for_system_network_configuration_discovery.yml,22 T1057,No,-,23 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,21 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,21 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1036.005,No,-,22 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1055,No,-,21 T1076,No,-,21 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_bruteforce.yml,19 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_desktop_network_traffic.yml,19 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1056.001,No,-,20 T1140,No,-,20 T1059,No,-,20 T1018,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_adfind_exe.yml,19 T1204.001,No,-,20 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,15 T1047,Yes,https://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml,15 T1033,No,-,19 T1189,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1560.001,No,-,18 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,16 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1116,No,-,16 T1553.002,No,-,16 T1503,No,-,16 T1112,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_reg_exe_process.yml,15 T1555.003,No,-,16 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1043,No,-,15 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1133,No,-,14 T1087.001,No,-,14 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_local_admin_account.yml,11 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/short_lived_windows_accounts.yml,11 T1049,No,-,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___advpack.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___setupapi.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_application_control_bypass___syssetup.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_dllregisterserver.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_startw.yml,5 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_with_no_command_line_arguments.yml,5 T1074.001,No,-,13 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike.yml,10 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/smb_traffic_spike___mltk.yml,10 T1085,No,-,13 T1045,No,-,13 T1027.002,No,-,13 T1046,No,-,13 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1113,No,-,12 T1087.002,No,-,12 T1063,No,-,12 T1190,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_zerologon_via_zeek.yml,11 T1555,No,-,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1560,No,-,12 T1136.002,No,-,12 T1041,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_snicat_sni_exfiltration.yml,11 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_disableantispyware_reg.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempt_to_stop_security_service.yml,9 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/unload_sysmon_filter_driver.yml,9 T1518.001,No,-,12 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1119,No,-,10 T1505.003,No,-,10 T1100,No,-,10 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1143,No,-,9 T1559.002,No,-,9 T1135,No,-,9 T1090.002,No,-,9 T1036.004,No,-,9 T1110,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml,8 T1068,Yes,https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,8 T1102.002,No,-,9 T1564.003,No,-,9 T1173,No,-,9 T1569.002,No,-,9 T1035,No,-,9 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1132.001,No,-,8 T1059.007,No,-,8 T1590.002,No,-,8 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml,7 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,6 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_outliers___mltk.yml,6 T1003.004,No,-,8 T1137,No,-,8 T1106,No,-,8 T1219,No,-,8 T1117,No,-,8 T1090,No,-,8 T1102,No,-,8 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml,6 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml,6 T1065,No,-,8 T1088,No,-,8 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1066,No,-,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 T1021.004,No,-,7 T1007,No,-,7 T1071,No,-,7 T1547.009,No,-,7 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml,5 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml,5 T1588.001,No,-,7 T1070,Yes,https://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml,6 T1552.001,No,-,7 T1023,No,-,7 T1098,No,-,7 T1027.005,No,-,7 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml,6 T1012,No,-,7 T1221,No,-,7 T1134,No,-,7 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1037,No,-,6 T1099,No,-,6 T1069,No,-,6 T1074.002,No,-,6 T1070.006,No,-,6 T1009,No,-,6 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_created_by_netsh.yml,4 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/processes_launching_netsh.yml,4 T1027.001,No,-,6 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_renamed.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_mshta_url_in_command_line.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rundll32_inline_hta_execution.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_child_process.yml,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_mshta_spawn.yml,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,5 T1170,No,-,6 T1027.003,No,-,6 T1059.006,No,-,6 T1194,No,-,6 T1084,No,-,6 T1001.002,No,-,6 T1055.001,No,-,6 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,5 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1040,No,-,5 T1120,No,-,5 T1550,No,-,5 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/detections/overwriting_accessibility_binaries.yml,4 T1087,No,-,5 T1020,No,-,5 T1015,No,-,5 T1566,No,-,5 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_renamed.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_spawn_child_process.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_url_in_command_line.yml,1 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_html_help_using_infotech_storage_handlers.yml,1 T1195.002,No,-,5 T1573.002,No,-,5 T1075,No,-,5 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/identify_new_user_accounts.yml,3 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,3 T1223,No,-,5 T1158,No,-,5 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,3 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,3 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,4 T1102.001,No,-,5 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1561.002,No,-,4 T1014,No,-,4 T1560.003,No,-,4 T1025,No,-,4 T1093,No,-,4 T1110.002,No,-,4 T1487,No,-,4 T1574.001,No,-,4 T1195,No,-,4 T1038,No,-,4 T1110.003,No,-,4 T1003.005,No,-,4 T1036.002,No,-,4 T1568,No,-,4 T1071.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_outbound_smb_traffic.yml,3 T1001,No,-,4 T1039,No,-,4 T1055.012,No,-,4 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 T1570,No,-,4 T1095,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,3 T1496,No,-,4 T1213,No,-,4 T1518,No,-,4 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ntdsutil_export_ntds.yml,-2 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml,-2 T1124,No,-,4 T1094,No,-,4 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1067,No,-,3 T1542.003,No,-,3 T1080,No,-,3 T1587.002,No,-,3 T1091,No,-,3 T1583.001,No,-,3 T1572,No,-,3 T1004,No,-,3 T1071.003,No,-,3 T1021.006,No,-,3 T1547.004,No,-,3 T1550.003,No,-,3 T1188,No,-,3 T1074,No,-,3 T1104,No,-,3 T1583.006,No,-,3 T1072,No,-,3 T1210,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml,2 T1199,No,-,3 T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,No,-,3 T1500,No,-,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-1 T1498,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-1 T1588.003,No,-,3 T1008,No,-,3 T1053.002,No,-,3 T1090.001,No,-,3 T1584.001,No,-,3 T1529,No,-,3 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1596.003,No,-,2 T1222.002,No,-,2 T1492,No,-,2 T1213.002,No,-,2 T1109,No,-,2 T1588.004,No,-,2 T1587.003,No,-,2 T1565.001,No,-,2 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1489,Yes,https://github.com/splunk/security_content/blob/develop/detections/windows_security_account_manager_stopped.yml,1 T1568.001,No,-,2 T1559.001,No,-,2 T1115,No,-,2 T1218.007,No,-,2 T1176,No,-,2 T1584.003,No,-,2 T1560.002,No,-,2 T1032,No,-,2 T1087.003,No,-,2 T1218.003,No,-,2 T1562.002,No,-,2 T1145,No,-,2 T1552.004,No,-,2 T1583.004,No,-,2 T1134.002,No,-,2 T1125,No,-,2 T1482,Yes,https://github.com/splunk/security_content/blob/develop/detections/nltest_domain_trust_discovery.yml,1 T1542.002,No,-,2 T1583.003,No,-,2 T1191,No,-,2 T1055.002,No,-,2 T1059.004,No,-,2 T1208,No,-,2 T1036.001,No,-,2 T1201,No,-,2 T1187,No,-,2 T1567.002,No,-,2 T1564.005,No,-,2 T1584.004,No,-,2 T1098.002,No,-,2 T1037.001,No,-,2 T1480.001,No,-,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_kerberoasting.yml,0 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1 T1021.005,No,-,1 T1110.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_number_of_login_failures_from_a_single_source.yml,0 T1216.001,No,-,1 T1546.013,No,-,1 T1501,No,-,1 T1123,No,-,1 T1568.002,No,-,1 T1172,No,-,1 T1606.002,No,-,1 T1484.002,No,-,1 T1586.001,No,-,1 T1527,No,-,1 T1497.001,No,-,1 T1053.003,No,-,1 T1070.002,No,-,1 T1218.004,No,-,1 T1214,No,-,1 T1565.003,No,-,1 T1552.002,No,-,1 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,0 T1137.006,No,-,1 T1556.002,No,-,1 T1070.003,No,-,1 T1586.002,No,-,1 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,-2 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2 T1010,No,-,1 T1182,No,-,1 T1547.005,No,-,1 T1483,No,-,1 T1183,No,-,1 T1574.006,No,-,1 T1092,No,-,1 T1585.002,No,-,1 T1557.001,No,-,1 T1042,No,-,1 T1101,No,-,1 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,0 T1218.008,No,-,1 T1055.013,No,-,1 T1504,No,-,1 T1558.001,No,-,1 T1137.001,No,-,1 T1138,No,-,1 T1546.009,No,-,1 T1568.003,No,-,1 T1606.001,No,-,1 T1134.001,No,-,1 T1205.001,No,-,1 T1528,No,-,1 T1098.001,No,-,1 T1491.001,No,-,1 T1552.006,No,-,1 T1048.002,No,-,1 T1497.002,No,-,1 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_changes_to_file_associations.yml,0 T1026,No,-,1 T1122,No,-,1 T1102.003,No,-,1 T1534,No,-,1 T1056.002,No,-,1 T1052.001,No,-,1 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,0 T1585.001,No,-,1 T1488,No,-,1 T1174,No,-,1 T1546.015,No,-,1 T1137.004,No,-,1 T1186,No,-,1 T1001.003,No,-,1 T1030,No,-,1 T1550.004,No,-,1 T1506,No,-,1 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_spawn.yml,-2 T1494,No,-,1 T1090.004,No,-,1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-1 T1557.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-1 T1493,No,-,1 T1565.002,No,-,1 T1146,No,-,1 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_ipv6_network_infrastructure_threats.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_port_security_violation.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_rogue_dhcp_server.yml,-3 T1200,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_traffic_mirroring.yml,-3 T1556.001,No,-,1 T1543.002,No,-,1 T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_destroyed.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_cloud_instances_launched.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 T1056.004,No,-,1 T1118,No,-,1 T1001.001,No,-,1 T1561.001,No,-,1 T1211,No,-,1 T1574.012,No,-,1